How Bug Bounty Uncovered A 5-Year-Old Vulnerability In Hours
ID: 6c05a4d5-048d-5196-ad4d-ff3f76bad2db
STIX ID: report--6c05a4d5-048d-5196-ad4d-ff3f76bad2db
Feed Name: HackerOne Blog
After acquiring PullRequest, HackerOne added PullRequest assets to its bug bounty program and within 48 hours a researcher reported a five‑year‑old blind Cross‑Site Scripting (XSS) in a customer rating form that could trigger when employees viewed submissions via archived unique rating links. HackerOne classified the issue as high severity (8.8/10), removed the unused vulnerable code, tightened Content Security Policy, began migrating legacy code to React, added expiration to rating links, and confirmed remediation via a retest with no evidence of prior exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
